Back Finance.Biggo Crypto Whale Loses $25.6 Million in Second Phishing Attack on Same Wallet
A cryptocurrency whale has been hit by a phishing attack for the second time in less than a year, losing approximately $25.6 million from a wallet that was previously drained of $24.2 million in September 2023. The latest breach, which occurred on August 12, saw the attacker quickly convert the stolen assets into Dai (DAI) and Ethereum (ETH) to facilitate movement of the funds.
Blockchain security firm PeckShield identified the largest single loss as $6.3 million worth of aWBTC, an Aave-wrapped version of Bitcoin. The attacker also made off with $5.1 million in Dai, $4.7 million in Wrapped Bitcoin (WBTC), and roughly $2.6 million in Ethereum. Smaller balances of Coinbase-wrapped Bitcoin (cbBTC), StableUSD (USDS), Lido DAO (LDO), and Curve DAO Token (CRV) were taken as well.
After seizing the funds, the attacker consolidated the proceeds into approximately 20 million DAI and 3,000 ETH, according to on-chain analyst Specter. PeckShield tracked the stolen assets to four new wallet addresses where the proceeds currently sit. Unlike the 2023 incident, no funds from the August 2024 attack have been returned to the victim.
The same wallet address was previously compromised in September 2023 through a phishing exploit that relied on malicious token approvals, a vulnerability where a victim unknowingly grants a third party unlimited spending access to their tokens. That incident resulted in the loss of 4,851 Rocket Pool ETH (rETH) and 9,579.2 Lido Staked ETH (stETH), which the attacker swapped for approximately 13,785 ETH and 1.64 million DAI. In a notable contrast, the 2023 attacker returned nearly 90 percent of the stolen funds, or roughly $21.8 million.
Combined, the two breaches have now cost the address almost $50 million. The most recent loss exceeds the one by $1.4 million on a gross basis, though the earlier incident's partial refund narrows the net difference considerably.
The whale's loss lands during a month of heightened activity in crypto-related security breaches. Research platform DefiLlama recorded 13 separate security incidents in August, with tracked losses exceeding $12 million. That figure does not include the whale's $25.6 million loss, which pushes the month's total significantly higher.
The largest single event tracked by DefiLlama prior to the whale breach involved payment processor Coinsbuy, which lost $7.9 million on August 9 after wallets on the Ethereum and TRON networks were compromised. Attackers reportedly moved quickly to launder the proceeds into privacy-focused cryptocurrencies.
Note: DefiLlama's August total of $12 million excludes the whale's $25.6 million loss.
Other incidents recorded during the period included losses by RRWallet, MOKE, LOOPSDAO, and RISEx, none of which approached the scale of either the Coinsbuy breach or the whale attack.
Security analysts have emphasized the importance of swift action when a wallet is suspected of being compromised. Recommended steps include revoking all malicious token approvals and transferring remaining assets to a new wallet to prevent further losses. The repeated targeting of this particular address highlights the persistent risk facing high-value wallet holders, who remain attractive targets for phishing operations even after suffering a prior breach.
The lack of any refund in the latest incident marks a sharp departure from the 2023 outcome. Whether the attacker will follow the prior precedent and return funds remains uncertain, but the victim's recovery prospects currently appear dim.
Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
